Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoying but it's a security emergency. If your bank was physically guarded by a security company who has been found to replace agents with puppets in 62 Macau banks, wouldn't the head of security interrupt their week-end to guard the bank and contract a new company? If CA revocation takes customers by surprise today, it's time to start revoking certs more regularly. Heck, if you don't answer to a request from your domain provider within 15 days, your domain can even be revoked. CAs are more important than that.